Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-967g-cjx4-h7j6: go-codec-dagpb vulnerable to panic when decoding invalid blocks

go-codec-dagpb is an implementation of the DAG-PB spec for Go. The dag-pb codec can panic when decoding invalid blocks. This issue has been patched in version 1.5.0.

ghsa
#git

go-codec-dagpb vulnerable to panic when decoding invalid blocks

High severity GitHub Reviewed Published Dec 28, 2022 • Updated Dec 29, 2022

Related news

CVE-2022-2584: fix: use protowire for Links bytes decoding · ipld/go-codec-dagpb@a17ace3

The dag-pb codec can panic when decoding invalid blocks.